ZeroHour

CVE-2026-83138

moderate

Privileged Takeover Flaw in Oracle Spares Management for E-Business Suite

CVSS 3.1
8.0 high
EPSS
Published
()
Modified
AI analysis

A difficult-to-exploit vulnerability in the Internal Operations component of Oracle Spares Management allows an attacker who already holds high privileges and has network access via HTTP to fully compromise the product. Successful attacks result in a complete takeover of Oracle Spares Management with high confidentiality, integrity, and availability impact, and because of a scope change the blast radius can extend to additional products in the E-Business Suite environment. The affected deployments are Oracle E-Business Suite releases 12.2.3 through 12.2.15 running the Spares Management product. The high privilege requirement and high attack complexity make opportunistic exploitation unlikely, but a compromised privileged account or malicious insider could abuse the flaw for lateral impact. No public proof of concept is known and no in-the-wild exploitation has been reported, and the CVE is not on the CISA Known Exploited Vulnerabilities catalog.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83138 to all E-Business Suite 12.2.3-12.2.15 environments running Spares Management. Restrict HTTP access to EBS internal operations endpoints to trusted networks and VPNs, and audit high-privileged account activity for misuse. Confirm whether Spares Management is deployed and enabled, since environments without the module are not directly exposed to this flaw.

Affected
Oracle Spares Management (Oracle E-Business Suite), Internal Operations component12.2.3-12.2.15
Estimated exposure
moderate≈ low thousands of on-premises E-Business Suite instances with the Spares Management module — Oracle publishes no install counts, but E-Business Suite is deployed at thousands of large enterprises worldwide and Spares Management is a niche module within it, so the affected subset is plausibly in the low thousands of instances.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Spares Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Spares Management. While the vulnerability is in Oracle Spares Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Spares Management. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.